Legal

Privacy policy

Last updated 26 July 2026

CTIF is a threat intelligence service. This policy explains two separate things: what we hold about you as a customer, and what we hold about the IP addresses our sensors observe attacking the internet. Both are covered because, under the GDPR, an IP address can itself be personal data.

Customer data

When you create an account we store your username, your email address, a bcrypt hash of your password (never the password itself), your plan and its expiry, and your personal API key. We record a per-day count of your API requests so the plan quota can be enforced. If you open a support ticket, we keep the ticket and its messages.

The lawful basis is performance of the contract between you and us. We do not sell customer data, we do not use it for advertising, and we do not run third-party advertising or analytics trackers on this site.

Payments

Subscriptions are paid in USDT on the TRON network. We store the order, the amount, the deposit address we assigned to it and the on-chain transaction reference. We never receive or store card numbers or bank details.

Threat intelligence data

Our sensors and honeypots record the source IP addresses of unsolicited connection attempts and attacks against infrastructure we operate, together with what the address did, when it was first and last seen, and public metadata about it (geolocation, ASN, ISP, reverse DNS, RDAP and WHOIS, Tor exit status). We do not collect this from customer networks, and we do not collect the content of anyone’s private communications.

The lawful basis is legitimate interest: preventing and detecting attacks on network and information systems. Recital 49 of the GDPR recognises network and information security as a legitimate interest. The data is limited to what an attacking host reveals by attacking, and the hostility score decays as an address stops being seen, so entries fall out of the feed on their own.

Retention

Account data is kept while the account exists and is deleted on request. Order records are kept for accounting purposes. Sensor observations are kept while they remain useful as intelligence and are aged out afterwards.

Cookies

We set only the cookies required to sign you in and to protect the sign-in form against cross-site request forgery. There are no advertising or cross-site tracking cookies, so no consent banner is required.

Your rights

If you are in the EU or the UK you may request access to your data, correction, erasure, restriction, portability, or object to processing based on legitimate interest. That last right also applies if you control an address that appears in the feed: write to us with the address and evidence of control and we will review it, remove false positives, and tell you what we hold.

Requests go to support@orvteam.com. We answer within 30 days.

Changes

If this policy changes materially we will update the date at the top of this page and notify active subscribers by email.